The security firm Fortinet has shown a new vulnerability (CVE-2010-2972) that is being used to exploit jailbroken Apple iPhones leveraging the PDF file format. A few weeks back, Apple fixed the security vulnerability (CVE-2010-1797) associated with viewing malicious PDF files in iOS 4.0.2 and iPad 3.2.2 firmwares.
The problem lies in the Compact Font Format, which is supported in popular document formats such as PDF. The interesting aspect here though is that this it is often used intentionally to jailbreak devices. However, as with any vulnerability, a scenario could exist where an attacker could jailbreak a phone for malicious purposes. The exploit FreeType.CFF.Jailbreak.Apple.Device.Buffer.Overflow jumped into fourth position in last month report.
For all updates regarding your iDevices, stay tuned by following us on Twitter and/or subscribing to our RSS feed.
Authors: _GadgetNews